Data Privacy & PDPA Compliance

Singapore: Personal Data Protection Act 2012 (PDPA) and PDPC data protection obligations

Select country

Review how this page describes privacy-law coverage for your school jurisdiction.

Last reviewed: March 2026

Our Commitment

River SIS processes personal data for school management operations including student administration, staff records, and school activities. For Singapore schools, this page summarises how our operational privacy practices align to the Personal Data Protection Act 2012 (PDPA) and the PDPC's core data protection obligations, including accountability, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, and notifiable data breach response.


Data Classification
ClassificationDescriptionExamples
PIIPersonally identifiable informationDatabase records, user profile images
ConfidentialSensitive operational dataApp configuration, environment secrets
AuditAccess and activity recordsDatabase audit logs, admin activity
InternalNon-personal operational dataApplication logs, container images

Security Measures
Encryption at Rest
  • DocumentDB: KMS encryption at cluster level
  • S3 buckets: AWS KMS server-side encryption
  • CloudWatch Log Groups: KMS encryption
  • Container registry (ECR): KMS encryption
Encryption in Transit
  • HTTPS only; TLS 1.2 minimum, TLS 1.3 preferred
  • Application to database: TLS enforced, plaintext rejected

Data Retention
Data CategoryStorageRetentionDeletion
Customer images (current)S3IndefiniteManual on request
Customer images (superseded)S330 daysAutomatic (S3 Lifecycle)
Database backupsDocumentDB30 daysAutomatic
Application logsCloudWatch7 daysAutomatic
Database audit logsCloudWatch90 daysAutomatic

Your Data Rights
Access and Correction

Singapore's PDPA provides individuals with rights to request access to personal data and information about its use or disclosure, and to request correction of inaccurate data. We support verified requests through customer administrators and internal review workflows.

Consent, Purpose, and Retention

Singapore's PDPA is built around consent, notification, purpose limitation, and retention limitation rather than a standalone GDPR-style erasure right. We therefore review deletion or withdrawal-related requests alongside the original collection purpose, customer instructions, and retention obligations.

Accuracy and Record Quality

The PDPA requires organisations to make reasonable efforts to ensure personal data is accurate and complete where likely to be used to make decisions or disclosed to others. Administrative controls and update workflows support those obligations.

Data Portability

Singapore has introduced a data portability framework under the PDPA, though scope and implementation depend on the applicable data class and operational context. Where appropriate and technically feasible, we support structured export paths.

Transfer Limitation and Breach Response

For Singapore coverage, we also focus on the transfer limitation obligation and notifiable data breach requirements. Where data is transferred outside Singapore, we aim to maintain a comparable standard of protection and apply incident-response processes that support timely assessment and notification.


Governance Schedule
Monthly

Review data classification, retention settings, access permissions, and operational changes that may affect privacy risk.

Quarterly

Conduct least-privilege access reviews, verify key security controls, and document material changes to processing activities or vendor arrangements.

Annually

Perform a fuller review of data inventories, test data-rights handling and deletion workflows, review incident-response readiness, and update this document.


Exercise Your Data Rights

To exercise any of your data rights or for privacy-related enquiries, please contact SchoolHero.io OÜ at info@riversis.com or by post at Harju maakond, Kuusalu vald, Pudisoo küla, Männimäe, 74626, Estonia.